Impact
WooCommerce Fortnox Integration allows a stored cross‑site scripting (XSS) flaw due to improper input neutralization in web page generation. An attacker can inject JavaScript that is persisted in the page and executed whenever a visitor views the affected content. This enables session hijacking, defacement, and theft of sensitive data. The weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the Wetail WooCommerce Fortnox Integration plugin for WordPress, with all releases up through version 4.5.6 impacted. No lower bound on contained versions is specified, implying that every version from the earliest available up to and including 4.5.6 is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation under current metrics. The issue is not listed in the CISA KEV catalog. Based on the stored‑XSS nature, the attack requires the ability to inject data that is later rendered by the plugin—likely through an authenticated administrative interface or a publicly writable field, though the exact prerequisite is inferred from the description.
OpenCVE Enrichment
EUVD